78% of organisations have found GDPR to be a huge drain on resources, poll finds

London, 2 July 2018 – A poll out today by ICSA: The Governance Institute and recruitment specialist The Core Partnership reveals that almost four-fifths (78%) of organisations surveyed have found becoming compliant with the EU’s General Data Protection Regulation (GDPR) to be a heavy burden on their resources; 9% of those surveyed were unsure and 13% felt that it had not been a heavy burden.

Many organisations had to hire additional staff or employ external consultants due to internal resource issues. Even when work was outsourced, sometimes at considerable expense, it was not necessarily problem free with one respondent stating that ‘We engaged external solicitors but they themselves saw in increased workload, which reduced their response time for us’. This was reinforced by another respondent who revealed that ‘Our issue was mainly one of resource. We started the exercise last summer but the data mapping took months. By the time we were ready to analyse it with our lawyers, they themselves were inundated and took some time to produce our GDPR readiness report.’

One critic bemoaned the fact that ‘Tech resources have been diverted from business improvements to compliance at a time when a UK company should be focussing on using technology to improve productivity and drive the business forward.’ Several respondents struck a more positive note, stating that ‘It has taken a considerable amount of time, but has provided us with a good opportunity to review contracts and arrangements with external suppliers’ and ‘It will improve our approach to data handling and ensure that our housekeeping is much better. It is definitely a good thing, but, for an SME with limited resources, implementation has been quite painful.’

Resource issues and outstanding issues with third party contractors contributed to the delay in hitting full compliance. Just 50% of organisations were fully compliant with GDPR when the new EU data protection regulation came into force on 25 May. Some 27% admitted to not being fully compliant in time, with the remaining 23% unsure.

According to Peter Swabey, Policy and Research Director at ICSA: The Governance Institute:

“Achieving full compliance has been extremely time-consuming for many organisations and there is some concern that ongoing compliance will continue to be burdensome. Many of the areas that were named as being problematic – coordination between jurisdictions; group-wide solutions; third-party engagement; and staff training – will continue to be of importance and will require organisations to review processes and procedures on an ongoing basis. It is important for organisations to keep in mind that 25 May was just the start.”

ICSA: The Governance Institute is the professional body for governance. We have members in all sectors and are required by our Royal Charter to lead ‘effective governance and efficient administration of commerce, industry and public affairs’. With over 125 years’ experience, we work with regulators and policy makers to champion high standards of governance and provide qualifications, training and guidance. Website: www.icsa.org.uk

The Core Partnership is a niche market recruitment consultancy working with Company Secretaries and their teams to advise on and resource their specialist interim and permanent manpower needs. With relevant professional backgrounds spanning back to the 1980s, The Core Partnership has a wealth of knowledge of the development and dimensions of the role of the Company Secretary. The team provides market advice on relevant qualifications and experience, conducts salary and benchmarking exercises and works throughout the UK and overseas recruiting at all levels to this specific discipline. Website: www.core-partnership.co.uk